Normalizing security audit data in XML-format

Chen Yinru, Kegang Diao, Istvan P. Orci, Mats E. Åström · KTH Publication Database DiVA (KTH Royal Institute of Technology) · 2004

The analysis of log data can be extremely difficult for an administrator due to a large volume of log data with various formats from a number of different sources. It is also impossible to get a more precise view of the network security without aggregating and correlating log data generated by different defending systems and tools. The paper described is to establish an intermediate and platform-independent representation to which all security log data can be normalized to. The work presented here is only a part of an ongoing project that aims at detecting intrusions by utilizing data-mining techniques. In this paper, the log format normalized is proposed and implemented in XML format. This XML log format is not only flexible, extensible and heterogeneous; it also satisfies the other requirements, such as being convenient and easy to share, transfer, and store among different computer systems. It is anticipated that the XML log format will facilitate further research work in intrusion detection.

Read the paper · More papers on PaperTik